vulnerability

FreeBSD: VID-07718e2b-d29d-11e5-a95f-b499baebfeaf (CVE-2016-1544): nghttp2 -- Out of memory in nghttpd, nghttp, and libnghttp2_asio

Severity
2
CVSS
(AV:L/AC:L/Au:N/C:N/I:N/A:P)
Published
Feb 13, 2016
Added
Dec 10, 2025
Modified
Dec 10, 2025

Description

Nghttp2 reports: Out of memory in nghttpd, nghttp, and libnghttp2_asio applications due to unlimited incoming HTTP header fields. nghttpd, nghttp, and libnghttp2_asio applications do not limit the memory usage for the incoming HTTP header field. If peer sends specially crafted HTTP/2 HEADERS frames and CONTINUATION frames, they will crash with out of memory error. Note that libnghttp2 itself is not affected by this vulnerability.

Solution

freebsd-upgrade-package-nghttp2
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.